ua-tracer
by Paul Kinlan
ua-tracer
what does a user agent actually fetch, follow & run?
Trace cwnmf6YQ
First seen: 2026-06-23 09:09:02.449 UTC
User-Agent: Mozilla/5.0 (compatible; CT-WP-Scanner/1.0; +https://example.com/bot)
What this user agent did
Directly-referenced assets:
✗ fetched CSS
✗ fetched JS
✗ fetched image
✗ fetched font (HTML)
Document-level link hints:
✗ fetched favicon
✗ fetched apple-touch-icon
✗ fetched web manifest
✗ fetched preload
✗ fetched prefetch
Second-level follows (proves it parsed the linking file):
✗ followed CSS background-image
✗ followed CSS @font-face
✗ followed manifest icon
✗ followed CSS @import
Frames (does it descend into iframes?):
✗ fetched iframe document
✗ descended into iframe (loaded inner image)
Reporting (a report-only CSP is violated by inline styles; reports can arrive via HTTP headers with no JS, or via in-page beacons):
✗ sent a CSP/Reporting report (any path)
✗ delivered via report-uri/Report-To header (no JS)
✗ delivered via in-page beacon (securitypolicyviolation / ReportingObserver)
Social embed (Open Graph / Twitter card images):
✗ fetched og:image
✗ fetched twitter:image
JavaScript execution:
✗ EXECUTED classic JS
✗ EXECUTED ES module
✗ posted client timing
Server-side request waterfall
Every request the server received for this trace, in receive order. +ms is the delta from the
homepage request.
| Received | Δ | Kind | Method | User-Agent |
|---|---|---|---|---|
| 2026-06-23 09:09:02.449 UTC | +0 ms | homepage | GET | Mozilla/5.0 (compatible; CT-WP-Scanner/1.0; +https://example.com/bot) |
request headers (8){
"accept": "text/html,application/xhtml+xml,application/json,*/*",
"accept-encoding": "gzip",
"connection": "close",
"host": "uatracer.com",
"traceparent": "00-20a2ad588b21fd588c1ad56e0556bbf7-bbdd11ab2f54aca3-01",
"tracestate": "",
"user-agent": "Mozilla/5.0 (compatible; CT-WP-Scanner/1.0; +https://example.com/bot)",
"via": "HTTP/1.1 ams.vultr.prod.deno-cluster.net"
}
|
||||